Compliance & AssessmentArticle 17
Quality Management System
A documented system that providers of high-risk AI systems must establish, implement, document, and maintain covering: the regulatory compliance strategy, design and development processes, data governance procedures, risk management, post-market monitoring, and incident reporting.
Related terms
- Conformity AssessmentThe process of verifying whether a high-risk AI system complies with the requirements set out in Chapter III Section 2 of the Regulation. Can be conducted…
- CE MarkingThe marking by which a provider indicates that a high-risk AI system is in conformity with the requirements set out in Chapter III Section 2 of the…
- EU Declaration of ConformityA statement made by the provider affirming that a high-risk AI system is in conformity with the provisions of the Regulation and all applicable Union…
- Fundamental Rights Impact AssessmentA structured assessment required under Article 27 for deployers of high-risk AI systems that are bodies governed by public law, or private operators…
- Post-Market MonitoringProactive collection and review of experience gained from the use of high-risk AI systems, to identify any need for corrective or preventive actions and…
- AI Regulatory SandboxA controlled environment established by a competent authority that offers providers and prospective providers of AI systems the possibility to develop,…
Related compliance controls
- RM-013Risk Management Roles and ResponsibilitiesProviders must assign clear roles and responsibilities for risk management activities, ensuring that personnel performing risk management tasks have the necessary competency, resources, and authority to fulfil their obligations.
- QM-001Quality Management System EstablishmentArticle 17(1) requires providers of high-risk AI systems to put in place a quality management system that ensures compliance with the requirements of the EU AI Act, documented in policies, procedures, and instructions.
- QM-002Regulatory Compliance StrategyProviders must establish and document a strategy for achieving and maintaining compliance with applicable regulatory requirements, including the EU AI Act, GDPR, and applicable national sector laws, with defined responsibilities and timelines.
- QM-003Design Control ProceduresProviders must implement documented design control procedures that ensure regulatory and performance requirements are systematically incorporated from the earliest design stages and verified at each major development milestone.
Upgrade when it needs to be
The free questionnaire returns preliminary signals. The Full Assessment turns real system material into a governed decision record - extraction, component separation, evidence, national overlays, and a review-ready dossier.
Start free risk preview